楼主: tonger2003
收起左侧

[病毒样本] 一包 卡7表现不佳

 关闭 [复制链接]
zzh161
发表于 2007-5-28 21:20:12 | 显示全部楼层
趋势启发报了20个

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
promised
发表于 2007-5-28 21:21:40 | 显示全部楼层
原帖由 zzh161 于 2007-5-28 21:20 发表
趋势启发报了20个

小声的说一句
PACKER。。。。。。令人浮想联翩
The EQs
发表于 2007-5-28 21:22:42 | 显示全部楼层
不发表任何评论ing。。。。。现在不敢确定到底是不是viking。。。vba32乱报的能力也是很强的。。。仙剑的壳报鸽子。。还有不少的壳也乱报
scottxzt
发表于 2007-5-28 21:23:17 | 显示全部楼层

19

Starting the file scan:

Begin scan in 'D:\Documents and Settings\dell\桌面\新建文件夹'
D:\Documents and Settings\dell\桌面\新建文件夹\
D:\Documents and Settings\dell\桌面\新建文件夹\Temp[1].part2.rar
  [0] Archive type: RAR
  --> Temp\Temp\srogm.exe
      [INFO]      Error multiple volume
  --> Temp\Temp\stpgldk.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
      [WARNING]   Infected files in archives cannot be repaired!
  --> Temp\Temp\svchost32.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
      [WARNING]   Infected files in archives cannot be repaired!
  --> Temp\Temp\svchost.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
      [WARNING]   Infected files in archives cannot be repaired!
  --> Temp\Temp\tlso0.dll
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
      [WARNING]   Infected files in archives cannot be repaired!
  --> Temp\Temp\tlso.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
      [WARNING]   Infected files in archives cannot be repaired!
  --> Temp\Temp\wdso0.dll
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
      [WARNING]   Infected files in archives cannot be repaired!
      [WARNING]   The file was ignored!
D:\Documents and Settings\dell\桌面\新建文件夹\Temp[1].part1.rar
  [0] Archive type: RAR
  --> Temp\Temp\wdso.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
      [WARNING]   Infected files in archives cannot be repaired!
  --> Temp\Temp\conime.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
      [WARNING]   Infected files in archives cannot be repaired!
  --> Temp\Temp\copypfh.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
      [WARNING]   Infected files in archives cannot be repaired!
  --> Temp\Temp\csrss.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
      [WARNING]   Infected files in archives cannot be repaired!
  --> Temp\Temp\ctfmon.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
      [WARNING]   Infected files in archives cannot be repaired!
  --> Temp\Temp\daso0.dll
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
      [WARNING]   Infected files in archives cannot be repaired!
  --> Temp\Temp\daso.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
      [WARNING]   Infected files in archives cannot be repaired!
  --> Temp\Temp\IEXPLORE.EXE
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
      [WARNING]   Infected files in archives cannot be repaired!
  --> Temp\Temp\mmc.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
      [WARNING]   Infected files in archives cannot be repaired!
  --> Temp\Temp\NhYPcmW.com
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
      [WARNING]   Infected files in archives cannot be repaired!
  --> Temp\Temp\services.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
      [WARNING]   Infected files in archives cannot be repaired!
  --> Temp\Temp\smss.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
      [WARNING]   Infected files in archives cannot be repaired!
  --> Temp\Temp\spglsdr.exe
      [DETECTION] Is the Trojan horse TR/Crypt.NSPM.Gen
      [WARNING]   Infected files in archives cannot be repaired!
  --> Temp\Temp\srogm.exe
      [INFO]      Error multiple volume
      [WARNING]   The file was ignored!


End of the scan: 2007年5月28日  21:22
Used time: 00:28 min

The scan has been done completely.

      1 Scanning directories
     22 Files were scanned
     19 viruses and/or unwanted programs were found
wangjay1980
发表于 2007-5-28 21:23:22 | 显示全部楼层
此毒是针对卡巴的,当然不会让你查出
zzh161
发表于 2007-5-28 21:24:23 | 显示全部楼层
原帖由 promised 于 2007-5-28 21:21 发表

小声的说一句
PACKER。。。。。。令人浮想联翩

这个我试了下,不完全是报壳,但是报了的基本上都是病毒,没有什么问题
promised
发表于 2007-5-28 21:25:04 | 显示全部楼层
VBA32可能报壳嫌疑,过几天我看看
现膜拜一下趋势杀软的报某壳能力,媲美红伞
是病毒和报壳有直接联系吗,LS可以去看一下逻辑方面的书籍

[ 本帖最后由 promised 于 2007-5-28 21:37 编辑 ]
The EQs
发表于 2007-5-28 21:25:16 | 显示全部楼层

回复 #15 wangjay1980 的帖子

不仅仅是针对卡巴。。。。。同时还针对nod32
l784588
发表于 2007-5-28 21:25:29 | 显示全部楼层
avast 报了,不错!
mhj144007
发表于 2007-5-28 21:25:38 | 显示全部楼层
可憐的Dr.Web
NhYPcmW.com;C:\Documents and Settings\Mahaijun\桌面\Temp\Temp;BackDoor.Pomax;;
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2024-5-3 09:46 , Processed in 0.095024 second(s), 15 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表